skills/tonone-ai/tonone/flux-health/Gen Agent Trust Hub

flux-health

Warn

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly instructs the agent to search for "connection strings" and configuration files for BigQuery, Redshift, and Snowflake (Step 0). These files and strings are primary locations for hardcoded database credentials, API keys, and service account tokens.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform discovery of migration directories, ORM configurations, and database connection strings. While intended for health checks, automated searching for sensitive configuration files increases the risk of credential exposure to the agent session.
  • [DATA_EXFILTRATION]: The instructions mandate the use of /atlas-report when analysis results exceed a 40-line limit. This indicates that detailed findings regarding data quality, schema drift, and pipeline status—which can reveal internal database architecture and sensitive data statistics—are sent to an external handler/service.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — flux-health